Skip to main content

infosecacademy Eğitim Danışmanlık Hizmetleri

ISO management systems

ISO management systems consulting — six standards, one integrated system

Six standards, all held at Lead Auditor level by our founder, implemented as one integrated management system wherever your scope allows it. Documentation is written from your actual processes, and the evidence trail is built with it.

ISO/IEC 27001:2022ISO/IEC 27701:2025ISO 22301:2019ISO/IEC 20000-1:2018ISO/IEC 42001:2023ISO 9001
Integrated, not stacked

Three systems, three document sets, three audit cycles that contradict each other

Organisations frequently arrive with exactly that. We consolidate: one context and scope, one risk method, one document control system, one internal audit programme, one management review — with standard-specific annexes. Less documentation, fewer audit days, fewer findings.

One risk method

Information security, continuity and privacy risks in the same methodology and the same register, repeatable every year.

One audit programme

A combined internal audit plan, shared evidence, a single finding register and single reporting.

One management review

Top management reviews every system in one meeting, with one decision record.

How we deliver

Implementation in nine steps

We do not treat certification as the finish line. The system has to survive the surveillance audit two years later without us.

  1. Gap analysis

    Current practice assessed against the standard’s requirements and controls, scored, with a prioritised remediation list.

  2. Context, scope and risk method

    Interested parties, boundaries, and a risk methodology the organisation can actually repeat annually.

  3. Risk assessment and treatment

    Threats, vulnerabilities and impacts identified and prioritised; treatment plan agreed with management.

  4. Documentation development

    Policies, procedures and records written to your processes, not imported from a template library.

  5. Implementation and integration

    Requirements embedded into live business processes, with the operational teams who will run them.

  6. Awareness and competence

    Role-based training so the people named in the documents know what they are responsible for.

  7. Internal audit and management review

    A full cycle completed before the external audit, with corrective actions closed.

  8. Certification support

    Certification body selection, Stage 1 and Stage 2 attendance, finding response and closure.

  9. Continual improvement

    Surveillance audit preparation and periodic review so the system does not decay between cycles.

Frameworks as implementation vehicles

Management system standards say what must be managed. Frameworks say what to deploy, and in what order. We use them underneath the ISO programme, not as slideware:

  • NIST CSF 2.0 — six functions including the new Govern function; maturity assessment and roadmap design, mapped to ISO/IEC 27001 and NIS2 Article 21
  • CIS Controls v8.1 — 18 prioritised controls in implementation groups IG1–IG3; the practical delivery engine for technical measures
  • ITIL 4 and ITIL (Version 5), released in stages during 2026 — practice design behind ISO/IEC 20000-1

Engagement summary

ISO/IEC 27001 duration
Typically 4–9 months, depending on scope and maturity
Delivered as
Word and Excel; version-controlled, metadata cleaned, document IDs applied
Language
English by default for EU clients; Turkish available
Certificate
Issued by the accredited certification body you select
Frequently asked questions

About ISO management systems

Does it make sense to implement several standards at once?

Where your scope allows it, yes. We build one context and scope, one risk method, one document control system, one internal audit programme and one management review, and keep the standard-specific requirements in annexes. The result is less documentation, fewer audit days and fewer findings.

Which standard should we start with?

For most organisations the backbone is ISO/IEC 27001: it answers NIS2 Article 21, GDPR security of processing and most customer security questionnaires with one system. Personal-data-heavy business models may put ISO/IEC 27701 first, and operations with low tolerance for disruption ISO 22301. We agree the sequence with you in the scoping call.

Does Infosec Academy issue the certificate?

No. Certificates are issued by accredited certification bodies, which under ISO/IEC 17021-1 may not provide consultancy. We implement the system, train your people, run the internal audit, and support you through the Stage 1 and Stage 2 audits by the certification body you select.

In which language are the documents produced?

English by default for EU clients and EU group companies, Turkish where the system operates in Türkiye. Every deliverable is version-controlled, metadata-cleaned and carries a document ID.

Let us start with a scoping conversation

Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.